LeakBase DragonCloudPrivate 17.5K Stealer Log: 123K Records Quietly Exposed
HEROIC analysts found that a stealer log titled DragonCloudPrivate 17.5K, published by a threat actor identified as Sonnyboyyyy on LeakBase, exposed 123,309 records on July 3, 2024. The compromised data includes email addresses, password hints, homepage URLs, usernames, and IP addresses, all harvested in plaintext from infected endpoints. This release is part of an ongoing DragonCloudPrivate series on LeakBase; a related release is also available: LeakBase DragonCloudPrivate 1k Logs by DusKid.
Why This Is Dangerous
Stealer logs deliver credentials exactly as they existed on the victim's device at the time of infection, bypassing any server-side encryption. Plaintext passwords and password hints contained in this log can be used immediately in credential stuffing attacks without any cracking step. The inclusion of homepage URLs tells attackers precisely which services the victim uses, allowing targeted, service-specific account takeover attempts rather than broad, untargeted spraying. IP addresses further expose the victim's network footprint.
What Was Exposed
- Email addresses
- Password hints
- Homepage URLs
- Usernames
- IP addresses
Why This Matters
Credentials extracted by infostealer malware are among the most operationally valuable data types in the underground economy because they require no further processing before use. Attackers use this data to conduct credential stuffing at scale across banking, e-commerce, and email platforms, leading directly to account takeovers, unauthorized financial transactions, and identity theft. The homepage URLs in this dataset also enable attackers to build precise target lists for follow-on phishing campaigns.
How Stealer Logs Work
Infostealer malware is typically distributed through phishing emails, malicious downloads, and trojanized software packages. Once installed on a victim's device, the malware silently harvests saved browser credentials, autofill data, clipboard contents, and session cookies. The collected data is exfiltrated to an attacker-controlled server and compiled into structured log files. These logs are then sold or freely shared on underground forums such as LeakBase, where other threat actors purchase or download them for use in downstream attacks.
Check If You Are Affected
HEROIC provides a free identity scanner that checks your email address against a database of over 400 billion compromised records, including stealer log releases like this DragonCloudPrivate dataset. Visit heroic.com to scan your email address at no cost and determine whether your credentials were captured in this or related infostealer campaigns.
Related Parts of This Breach
Breach Breakdown
123,309 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds